IP Library › Granted Patent US 12,369,029
Granted Patent B2
US 12,369,029 · App. 17/670,915 · Granted Jul 22, 2025

Dynamic access policy provisioning in a device fog

Inventors: Ned M. Smith (Beaverton, OR); Nathan Heldt-Sheller (Portland, OR)
Assignee: Intel Corporation
H04W12/08G06F21/6218H04L41/0893H04L63/102H04L63/20H04W4/38H04L41/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,369,029
App. No.
17/670,915
Granted
Jul 22, 2025
Kind
B2
Abstract

Various systems and methods for dynamic access policy provisioning in a connected device framework are described herein. In an example, the techniques for policy provisioning may include resource update access policy automation, directory resource access policy automation, or hidden resources access policy automation, as monitored and operated with an access management service (AMS). In an example, the AMS monitors resources to receive a notification when they change. If the change observed is an addition or deletion of a resource object, the AMS responds by performing security analysis of devices hosting the new resource(s), which may further result in device onboarding actions. The AMS may further respond by evaluating link semantics to determine which other devices and resources may need updated access control list (ACL) policies.

Claims (43)

1. An apparatus comprising:

memory; and

machine executable instructions; and

programmable circuitry to at least one of instantiate or execute the machine executable instructions to at least:

identify a creation of a resource based on a first specific command output by a resource host and observed on an Internet of things (IoT) network, the first specific command performed with a device to create the resource, the resource not accessible on the IoT network, the identification of the creation based on a change to (a) a directory or (b) collection resource managing a plurality of resources and devices within the IoT network based on the creation of the resource;

generate a first access control entry based on the creation, the first access control entry to include matching criteria corresponding to access to the resource by a subject client, the first access control entry to provide access to the resource according to the directory or the collection resource;

identify a deletion of the resource that is not accessible on the IoT network, the deletion identified based on a second specific command output by the resource host and observed on the IoT network, the second specific command referencing the resource;

generate a second access control entry based on the deletion; and

cause transmission of the second access control entry to the resource host.

2. The apparatus of claim 1 , wherein the first specific command is a create command.

3. The apparatus of claim 1 , wherein the programmable circuitry is to identify the change in response to a notification.

4. The apparatus of claim 1 , wherein the change is an anticipated change.

5. The apparatus of claim 1 , wherein the resource is in a collection hosted by the resource host.

6. The apparatus of claim 5 , wherein the collection includes one or more links to respective resources of the IoT network.

7. The apparatus of claim 1 , wherein the matching criteria includes at least one of (a) a subject matching criterion corresponding to a first applicability of the first access control entry to the subject client or (b) a resource matching criterion corresponding to a second applicability of the first access control entry to the resource, the subject matching criterion identifying the subject client based on at least one of identity, role, a first wildcard, or a subject resource, the resource matching criterion identifying the resource based on at least one of a second wildcard, a reference, a resource type, an interface, or attributes defined by a link structure.

8. The apparatus of claim 1 , wherein the programmable circuitry is unaware of the resource prior to the observation of the first specific command on the IoT network.

9. The apparatus of claim 1 , wherein the first specific command does not identify the programmable circuitry.

10. The apparatus of claim 1 , wherein the first specific command does not identify the programmable circuitry.

11. The apparatus of claim 1 , wherein the resource is a hidden resource.

12. A non-transitory computer readable storage medium comprising instructions to cause one or more processors to at least:

identify a creation of a resource based on a first specific command output by a resource host and observed on an Internet of things (IoT) network, the first specific command performed with a device to create the resource, the resource not accessible on the IoT network, the identification of the creation based on a change to (a) a directory or (b) collection resource managing a plurality of resources and devices within the IoT network based on the creation of the resource;

generate a first access control entry based on the creation, the first access control entry to include matching criteria corresponding to access to the resource by a subject client, the first access control entry to provide access to the resource according to the directory or the collection resource;

identify a change to the resource that is not accessible on the IoT network, the change identified based on a second specific command output by the resource host and observed on the IoT network, the second specific command referencing the resource;

generate a second access control entry based on the identified change; and

cause transmission of the second access control entry to the resource host.

13. The non-transitory computer readable storage medium of claim 12 , wherein the first specific command is a create command.

14. The non-transitory computer readable storage medium of claim 12 , wherein the instructions cause the one or more processors to identify the change in response to a notification.

15. The non-transitory computer readable storage medium of claim 12 , wherein the change is an anticipated change.

16. The non-transitory computer readable storage medium of claim 12 , wherein the change to the resource corresponds to at least one of a change, an update, or a deletion of the resource in a collection hosted by the resource host.

17. The non-transitory computer readable storage medium of claim 16 , wherein the collection includes one or more links to respective resources of the IoT network.

18. The non-transitory computer readable storage medium of claim 12 , wherein the matching criteria includes at least one of (a) a subject matching criterion corresponding to a first applicability of the first access control entry to the subject client or (b) a resource matching criterion corresponding to a second applicability of the first access control entry to the resource, the subject matching criterion identifying the subject client based on at least one of identity, role, a first wildcard, or a subject resource, the resource matching criterion identifying the resource based on at least one of a second wildcard, a reference, a resource type, an interface, or attributes defined by a link structure.

19. The non-transitory computer readable storage medium of claim 12 , wherein the resource is a hidden resource.

20. A method comprising:

identifying, by executing an instruction with one or more processors, a creation of a resource based on a first specific command output by a resource host and observed on an Internet of things (IoT) network, the first specific command performed with a device to create the resource, the resource not accessible on the IoT network, the identification of the creation based on a change to (a) a directory or (b) collection resource managing a plurality of resources and devices within the IoT network based on the creation of the resource;

generate a first access control entry based on the creation, the first access control entry to include matching criteria corresponding to access to the resource by a subject client, the first access control entry to provide access to the resource according to the directory or the collection resource;

identifying, by executing an instruction with the one or more processors, an update of the resource that is not accessible on the IoT network, the update identified based on a second specific command output by the resource host and observed on the IoT network, the second specific command referencing the resource;

generating, by executing an instruction with the one or more processors, a second access control entry based on the update; and

transmitting the second access control entry to the resource host.

21. The method of claim 20 , wherein the first specific command is a create command.

22. The method of claim 20 , further including identifying the change in response to a notification.

23. The method of claim 20 , wherein the change is an anticipated change.

24. The method of claim 20 , wherein the update to the resource corresponds to at least one of a change or a deletion of the resource in a collection hosted by the resource host.

25. The method of claim 20 , wherein the matching criteria includes at least one of (a) a subject matching criterion corresponding to a first applicability of the first access control entry to the subject client or (b) a resource matching criterion corresponding to a second applicability of the first access control entry to the resource, the subject matching criterion identifying the subject client based on at least one of identity, role, a first wildcard, or a subject resource, the resource matching criterion identifying the resource based on at least one of a second wildcard, a reference, a resource type, an interface, or attributes defined by a link structure.

Continuity (3)
Continuation 16610835
Provisional Application 62505643 · May 12, 2017
Related Publication 20220248226A1 · Aug 4, 2022
References Cited (27)
US 11284259B2 · Smith et al. · 2022 [cited by applicant]
US 20050262132A1 · Morita · 2005 [cited by examiner]
US 20140359131A1 · Seed · 2014 [cited by examiner]
US 20150019714A1 · Shaashua · 2015 [cited by examiner]
US 20160105305A1 · Pignataro · 2016 [cited by examiner]
US 20160212099A1 · Zou · 2016 [cited by examiner]
US 20160337144A1 · Kim · 2016 [cited by examiner]
US 20160366136A1 · Heldt-Sheller · 2016 [cited by examiner]
US 20160366183A1 · Smith · 2016 [cited by examiner]
US 20170006528A1 · Bari · 2017 [cited by examiner]
US 20170093915A1 · Ellis · 2017 [cited by examiner]
US 20170295181A1 · Parimi · 2017 [cited by examiner]
US 20180212768A1 · Kawashima · 2018 [cited by examiner]
US 20180225354A1 · Li · 2018 [cited by examiner]
US 20180270314A1 · Mladin · 2018 [cited by examiner]
US 20180316563A1 · Kumar · 2018 [cited by examiner]
US 20190288913A1 · Salgueiro · 2019 [cited by examiner]
US 20200137119A1 · Jin · 2020 [cited by examiner]
WO 2018209323 · 2018 [cited by applicant]
Patent Cooperation Treaty, “International Preliminary Report on Patentability,” issued in connection with International Application Serial No. PCT US2018 032465, dated Nov. 21, 2019, 10 pages. [cited by applicant]
Patent Cooperation Treaty, “International Search Report,” issued in connection with International Application Serial No. PCT/US2018/032465, dated Aug. 30, 2018, 6 pages. [cited by applicant]
Patent Cooperation Treaty, “Written Opinion,” issued in connection withInternational Application Serial No. PCT/US2018/032465, dated Aug. 30, 2018, 8 pages. [cited by applicant]
Hartke, Universitaet Bremen Tzi, “Observing Resources in the Constrained Application Protocol (CoAP) rfc7641.txt”, Observing Resources in the Constrained Application Protocol COAP rfc7641.txt Internet Engineering Task F… [cited by applicant]
“OCF Security Specification V1.0.0”, Open Connectivity Foundation (OCF), [Online] Retrieved from the internet:https://openconnectivity.org draftspecs OCF_Security_Specification_vl.0.0.pdf, (Mar. 22, 2017), 104 pgs. [cited by applicant]
“OCF Core Specfication V1.0.0 Part 1”, Open Connectivity Foundation (OCF), (Mar. 22, 2017), 175 pgs. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance and Fee(s) Due,” issued in connection with U.S. Appl. No. 16/610,835, dated Nov. 12, 2021, 15 pages. [cited by applicant]
Mobile Edge Computing Introductory Technical White Paper, Sep. 1, 2014 (Sep. 1, 2014), 36 pages. [cited by applicant]